A critical vulnerability dubbed "Rogue Agent" discovered by Varonis could have allowed attackers with edit rights on a single Google Dialogflow CX chatbot to compromise all other bots sharing the same project. By exploiting a writable configuration file in Google's shared Code Block runtime, a malicious insider could overwrite the environment to steal live conversation data, exfiltrate user inputs, and inject phishing messages without triggering any alerts. Although the flaw required authenticated access and has since been patched by Google with no known real-world exploitation, it highlights a dangerous gap where standard content-edit permissions effectively grant arbitrary code execution across an entire organization's AI agents. Developers using Dialogflow CX with custom Code Blocks should immediately audit their dialogflow.playbooks.update permissions and review access logs from early 2026 to ensure no unauthorized changes occurred during the vulnerability window.